Impact
An attacker can derive the private key corresponding to the configured fee collector address and impersonate the collector.
The attacker can then call collectFee() to transfer both WETH fees and native ETH held by Snow to the attacker-controlled collector address. The attacker can subsequently call changeCollector() to permanently redirect future fee collection to an attacker-controlled address.
This results in unauthorized protocol-fee theft and persistent redirection of future fees.
Description
# Root + Impact
## Description
The Snow contract stores a fee collector address in `s_collector` and restricts fee collection and collector changes through `onlyCollector`.
The deployed collector address is configured using `makeAddr("collector")`. Foundry's `makeAddr()` deterministically derives its private key as:
`uint256(keccak256(abi.encodePacked("collector")))`
Therefore, the private key corresponding to the configured collector address is publicly computable by anyone.
An attacker can derive this private key, impersonate the configured collector, call `collectFee()`, and receive the WETH and native ETH accumulated by the Snow contract. The attacker can then call `changeCollector()` and replace the collector with an attacker-controlled address, redirecting future fees as well.Risk
Likelihood:
Likelihood
High
- The collector private key is deterministically derived from the publicly known string "collector".
- The private key can therefore be calculated without compromising any account, secret, oracle, or external dependency.
- Once the vulnerable collector configuration is deployed, an attacker can immediately authenticate as the collector.
- No victim interaction is required.
Risk — Likelihood
- The collector private key is deterministically derived from the publicly known string `"collector"`.
- The private key can therefore be calculated without compromising any account, secret, oracle, or external dependency.
- Once the vulnerable collector configuration is deployed, an attacker can immediately authenticate as the collector.
- No victim interaction is required.
Risk — Impact
- The attacker can call `collectFee()` and withdraw the WETH accumulated as protocol fees.
- The attacker can also receive the native ETH accumulated by the Snow contract.
- The attacker can call `changeCollector()` and replace the collector with an attacker-controlled address.
- Future protocol fees can subsequently be redirected to the attacker's collector address.
Impact:
Impact
An attacker can derive the private key corresponding to the configured fee collector address and impersonate the collector.
The attacker can then call collectFee() to transfer both WETH fees and native ETH held by Snow to the attacker-controlled collector address. The attacker can subsequently call changeCollector() to permanently redirect future fee collection to an attacker-controlled address.
This results in unauthorized protocol-fee theft and persistent redirection of future fees.
The contest is live. Earn rewards by submitting a finding.
Submissions are being reviewed by our AI judge. Results will be available in a few minutes.
View all submissionsThe contest is complete and the rewards are being distributed.